Report: CVE-2026-32124 - OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS)

Report: CVE-2026-32124 - OpenEMR: Dynamic Code Picker Renders Unescaped Descriptions (Stored XSS)

CVE ID :CVE-2026-32124 Published : March 11, 2026, 8:50 p.m. | 38 minutes ago Description :OpenEMR is a free and open source electronic health records and medical practice management application. Prior to 8.0.0.1, the dynamic code picker AJAX endpoint returns code descriptions (code_text) that are rendered in the front end (e.g. DataTables) without HTML escaping. If an administrator (or user with code management rights) creates or edits a code with a malicious description containing script, that script runs in the browser of every user who uses the picker. This vulnerability is fixed in 8.0.0.1. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Published
March 11, 2026